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Abstract Recently Xia and Song [Phys. Lett. A (In press)] have proposed a controlled quantum 
secure direct communication (CQSDC) protocol. They claimed that in their protocol only with 
the help of the controller Charlie, the receiver Alice can successfully extract the secret message 
from the sender Bob. In this letter, first we will show that within their protocol the controller 
Charlie's role can be excluded due to their unreasonable design. We then revise the Xia-Song 
CQSDC protocol such that its original advantages are retained and the CQSDC can be really 
realized. 
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Different from quantum key distribution (QKD)[l-2] whose object is to distribute a common key be- 
tween the two remote legitimate users of communication, quantum secure direct communication (QSDC) 
can transit the secret messages directly without creating first a key to encrypt them. Lately, many 
QSDC protocols have been proposed and actively pursued by some groups [3-20] since Beige et al.[3] first 
proposed a QSDC protocol taking advantage of Einstein-Podlosky-Rosen (EPR) pairs. Very recently, 
Xia and Song[10] presented a controlled QSDC protocol using a non-symmetric quantum channel with 
quantum superdense coding (referred to as the Xia-Song CQSDC protocol hereafter). 

Xia and Song [10] claimed that their protocol is a novel protocol for the implementation of controlled 
QSDC by using the particles in different dimension's Hilbert space. In their protocol they combined the 
ideas of block transmission, entanglement swapping, and quantum dense coding in the non-symmetric 
quantum channel. The communication is secure under some eavesdropping attack and two users can 
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transmit their secret messages with the help of controller Charlie securely and simultaneously. The 
efficiency of information transmission is also successfully increased. We agree that all these are advan- 
tages of their protocol except for one very important point. Since the Xia-Song CQSDC protocol is a 
controlled QSDC protocol, the controller's role should be indispensable. Nevertheless, we find that in 
their protocol the so-called controller Charlie is unvalued in fact. In this letter we will point out this 
leak and explain why Charlie is unvalued. Moreover, we will revise the Xia-Song CQSDC protocol such 
that its original advantages are retained and the CQSDC can be really implemented. 

Before pointing out the leak in the Xia-Song CQSDC protocol, let us briefly review the scenario Xia 
and Song considered and their two design ideas which we think are quite unreasonable. Xia and Song 
consider the following scenario. Suppose there are three involved parties Alice, Bob and Charlie. Alice 
and Bob are the secret message receiver and sender, respectively. Alice and Bob want to implement 
their direct secret communication. Charlie is a controller introduced to control the secret communication 
between Alice and Bob. To achieve this goal, when designing their protocol, Xia and Song take the 
following two ideas. (1) Alice is assigned to prepare a series (TV) of 2-dimensional GHZ entangled states 
in I^^abc = ^=(|000) + |111))abc and a series (M) of 3-dimensional Bell-basis states in \<&)a'B' = 
-^7j(|00) + |11) + \22))a'B'- She transmits the Sb sequence (consists of all -B's and B"s) to Bob for later 
secret message communication and the S c (consists of all c's) sequence to Charlie as his later control. 
That is to say, Alice is the quantum channel constructor. (2) Alice is assigned to finally judge whether 
the quantum channel is secure through comparing her measurement results with Bob's and Charlie's. If 
Alice announces that the quantum channel is secure, then Bob sends his secret message via his encodings 
and thinks Alice can extract the secret message only with Charlie's help. That is to say, Alice is also 
the quantum channel security checker. 

Now let us extensively analyze two design ideas in the Xia-Song CQSDC protocol. It is intriguing 
to ask, in the the scenario Xia and Song considered, who wants to let the QSDC be controlled by the 
controller Charlie? Essentially, this is an very important question and should be in prior considered. 
Otherwise, an unreasonable protocol may be designed, as can be seen in the Xia-Song CQSDC protocol. 
In the Xia-Song CQSDC protocol, Alice is the secret message receiver. Is she willing to receive Bob's 
secret message with control of Charlie? Of course, in a normal case, she is not. Then why she sends 
the S c sequence to Charlie as his control of the communication between her and Bob, can only be 
explained as the demand of Bob (not of Charlie, because Alice is the quantum channel constructor. If 
it is Charlie who demands Alice to let him control the secret communication between Alice and Bob, 
Alice can disregard Charlie's demand or just sends him a fake signal to cheat him. In this case, the 
communication between her and Bob can be successfully implemented). That is to say, Bob wants to 
let Alice retrieve his secret message only with Charlie's help. In this case, if Alice wants to exclude 
Charlie's control, what can she do? She can send a fake sequence S' c to Charlie and keeps the sequence 
S c in her site. If so, obviously both Bob and Charlie can not find Alice's this cheating, because in the 
Xia-Song CQSDC protocol Alice is the party who finally judges whether the quantum channel is secure. 
Consequently, after Bob encodes his secret message, Alice can obtain Bob's secret message without 
Charlie's help. This is the leak of the Xia-Song CQSDC protocol. The controller's role can be excluded 
by the receiver. The basic reason which induces this unexpected result is that Alice is assigned to be 
not only the quantum channel constructor but also the quantum channel security checker. 

If let different parties to act as the quantum channel constructor and the quantum channel security 
checker, respectively, then it seems that the leak in the Xia-Song CQSDC protocol can be fixed imme- 
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diately. In fact, if Alice is still assigned as the quantum channel constructor or the quantum channel 
security checker, it is quite possible that she has potential to cheat the other two such that she can 
exclude Charlie's control and obtain Bob's secret message without Charlie's help. Because the secret 
message is initially in Bob's hand, only if he thinks that the quantum channel is secure he will encode his 
secret message. Otherwise, the CQSDC is aborted. Hence in the following we will revise the Xia-Song 
CQSDC protocol in such a way that Bob is assigned to be both the quantum channel constructor and 
the quantum channel security checker, its original advantages are retained and the CQSDC can be really 
realized. Moreover, in the revised version the security check of quantum channel is varied in terms of 
randomly choosing measuring basis so that the security of quantum channel can be assured. One will 
see this later. Hence the revised version is not a simple exchange between Alice and Bob of the original 
Xia-Song CQSDC protocol. For convenience, in the revised version we will quote some descriptions and 
notations in the original Xia-Song CQSDC protocol. For completeness, we dctailcdly show the 9 steps 
of the revised version as follows: 

(SI) Bob prepares a series (N) of 2-dimensional GHZ entangled states in 

|*i)abc = ^(|000) + |111))abc, (1) 
and a series (M) of 3-dimensional Bell-basis states in 

l*W = ^(|00) + |ll) + |22)W, (2) 

where particles A, B and c are all in 2-dimcnsional Hilbert space, particles A' and B' are both in 
3-dimcnsional Hilbert space, and A (A') represents "travel", B (B 1 ) labels "home", and c stands for 
"control". Here Alice and Bob agree on that the six collective unitary operations U\, U2, U3, U4, 
U5 and Uq (see Eq. (9) in Ref.[10]) correspond to the secret messages 00, 01, 10, 11, 20 and 21, 
respectively. During the security check, they can use two sets of measuring bases (MBs), Z={|0), |1)} 
and X={\ +x) = ^(|0) + |1)), | — x) = ^(|0) — |1))} to measure the sample particles of 2-dimensional 
GHZ entangled state randomly. For the 3-dimensional Bell-basis state, there are four such complete 
bases. The Z-MB is composed of the eigenvectors \Z_ X ) = |0), \Z ) = |1) and \Z +1 ) = |2). The X-MB 
is chosen as 

|X-i) = ^(|0) + |l> + |2», (3) 

\X ) = 4=(l°> + e2W3 |!} + e~ 2 " /3 |2)), (4) 
V3 

\X +1 ) = 4=(|0) + e- 2W3 |l) + e 2 ™ /3 |2)). (5) 
V3 

The two other bases are formed by 

-^=(e 2ni/3 \0) + |1) + |2)) and cyclic permutation (6) 
v3 

and 

_L( e -2iri/3| ) + |i) + |2)) and cyclic permutation. (7) 
V3 

Alice and Bob randomly use one of the four MBs to measure the sample particles of 3-dimcnsional 
Bell-basis states during the security check. 
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Bob takes particle A' from each 3-dimensional Bell-basis state and particle A from each 2-dimcnsional 
GHZ entangled state to form an ordered particle groups [Pi(A'A), P 2 (A'A), Pn(A'A)], called Sa se- 
quence. Then he sends the Sa sequence to Alice. Where the subscripts indicate each 2-dimensional 
GHZ entangled state's and each 3-dimcnsional Bell-basis state's order in the sequence. Similarly he 
generates Sb sequence and keeps it in his site. He transmits the particles c (called the S c sequence 
hereafter) to Charlie in order. 

(52) Alice and Charlie publicly confirm that they have received the Sa sequence and S c sequence, 
respectively. They store the Sa sequence and S c sequence according to their coming orders. If Bob 
wants to transmit messages to Alice, he randomly picks out a sufficiently large subset of particle groups 
from the Sb sequence as sample particle groups to check the security of the transmission. The remaining 
particle groups in the S b sequence are taken as encoding-decoding particle groups for his later encoding 
via local unitary operations U m (m £ 1, 2, 6). 

(53) For each checking group, the security check consists of two parts, i.e., the security check of 
2-dimensional GHZ entangled state and the security check of 3-dimensional Bell-basis states, which can 
be completed with the following procedures, (a) Bob tells Alice and Charlie the sample particle groups 
that he has chosen. Then Alice and Charlie pick out the corresponding particle groups and particles 
from Sa sequence and S c sequence. For instance, if Bob chooses P\(B'B), Alice and Charlie should 
choose Pi(A'A) and c\. (b) Bob randomly chooses the Z-MB or X-MB to measure the chosen particles 
B' and B. (c) Alice and Charlie also randomly choose the Z-MB or X-MB to measure the corresponding 
particles A' , A and c. (d) Bob randomly selects Alice or Charlie to tell him the corresponding MBs 
chosen and the measurement results. Such random ordering of who tell first can prevent cheating. This 
check procedure is an important improvement of the original protocol, (e) Alice, Bob and Charlie have 
25% probability to choose the same MBs, i.e., they all choose Z-MB or X-MB simultaneously, when they 
all choose the same MBs, Bob compares his measurement results with Alice's and Charlie's to check 
the existence of Eve. The intercept-and-resend attack as well as the entangle-and-measure attack can 
be detected efficiently by this method. If no eavesdropping exists, their measurement results should be 
completely correlated in an ideal condition. For instance, during the security check of 2-dimensional GHZ 
entangled state, if their measurement outcomes coincide when they use the same basis in order according 
to Eqs. (11)-(18) in Ref.[10], they go to check 3-dimensional Bell-basis states' security. Otherwise, they 
have to discard their transmission and abort the communication. If there is no Eve in line, the procedure 
goes to (S4), otherwise they discard the communication. 

(54) Bob asks Charlie to perform a Hadamard operation on each c„ in order. The Hadamard 
operation takes the form 

if|0> = -L(|0) + |l», (8) 

ff|l> = ^(|0)-|l», (9) 
which will transform the state shown in Eq. (1) into 

|*i)„ = -^=[(|00) + |ll»A n s n ® |0) Cn + (|00) - \U)) AnBn ® |l)cj- (10) 

If Charlie would like to help Alice and Bob to communication, he first performs a Hadamard operation 
on each c„ in order. Then he measures photon c n and informs Alice and Bob of his measurement results 
via classical communication. The procedure goes to (S5); otherwise, Charlie do nothing on photon c n . 
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Without the help of controller Charlie, there will be no perfect quantum channel between Alice and 
Bob. As a consequence, Alice cannot extract Bob's secret messages solely (she can only read 1 bit 
information), and the controlled quantum secure direct communication protocol failed. 

(55) Charlie measures his photon c n . If Charlie obtains the outcome |0) Cn , photons (h n ,t n ) will 
collapse into the state 

\t>t)n = l(\00) + \n)) AnBn ; (11) 
otherwise, we propose that the state of photons (h n ,t n ) will be 

l*r>n = ^(|00)-|ll)) jlBBB . (12) 

After the above operations, in accord with the encoding-decoding group ordering, Charlie informs Alice 
and Bob of his measurement results via classical communication. 

(56) In accord with the encoding-decoding particle groups ordering, Bob encodes his secret messages 
by performing one of the six local collective unitary operations U\, U2, U3, U4, U5 and Uq on particles 
£>', B of each P^B'B) except the sample particles according to his secret messages (say, 0001 . . .) 
need to be transmitted this time: for instance, U\ operation on group 1 to encoding 00. U 2 operation 
on group 2 to encode 01, etc. After the unitary U operations, Bob makes the measurements on particle 
groups B', B under the basis {|* o>, |*oi>, |*io>, |*n>, |*20>, |*2i» (see Eq. (3)-(8) in Rcf.[10]). 

(57) Bob publicly announces his measurement results and the position of the particle group B' and 

B. 

(58) Alice measures the particle groups A', A of the corresponding Pi(A'A) except the sample 
particles under the basis {l^oo), l^oi), l^io), l^n), |^2o); l*2i)}- After the measurements, Alice can 
conclude the exact local collective unitary operations performed by Bob according to Bob's measurement 
results and the position of particle groups B', B and her own measurement results of particles A', A. 
Hence Alice can successfully get Bob's secret messages. 

(59) The controlled QSDC has been successfully completed. 

So far, we have shown the revised version of the Xia-Song CQSDC protocol. If the sender Bob wants 
to transmit messages to the receiver Alice, the controller Charlie must take a Hadamard operation on 
each of his particles, measure it, and tell the results to Bob and Alice in order. Our version can also be 
generalized to multi-party control system. TV-party share a large number of TV-particle 2-dimensional 
GHZ entangled states. Party M (M G N) as receiver, party Q (Q G N,Q 7^ M) as sender, and 
N — 2 parties except for party M and party Q as controller. The multi-party controlled QSDC can 
also succeed. The security analyses of our this CQSDC protocol is the same as the Xia-Song CQSDC 
protocol. 

To summarize, in this letter we have pointed out a flaw in the original Xia-Song CQSDC protocol, 
that is, within their protocol the controller Charlie's role can be excluded. We have revised the original 
Xia-Song CQSDC protocol such that its advantages are retained and the CQSDC can be really achieved. 
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